NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2239  CVE-2008-2318  The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the requests for these URLs.    Medium  2017-01-03  2011-03-07  View
36287  CVE-2014-9668  The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting length values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Web Open Font Format (WOFF) file.    7.5  High  2017-01-19  2017-01-02  View
37636  CVE-2013-1431  The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows remote attackers to bypass TLS verification and perform a man-in-the-middle attacks.    6.8  Medium  2017-01-18  2016-11-08  View
77628  CVE-2001-0148  The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the "Frame Domain Verification" vulnerability.    7.5  High  2017-01-05  2008-09-05  View
23278  CVE-2015-0844  The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1) campaign or (2) map file.    Medium  2017-01-19  2016-06-28  View

Page 2638 of 17672, showing 5 records out of 88360 total, starting on record 13186, ending on 13190

Actions